PT-2023-22354 · D Link · D-Link Dir-823G

CVE-2023-29665

·

Published

2023-04-17

·

Updated

2023-04-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR823G version 1.0.2B05
Description A stack overflow issue was discovered via the NewPassword parameters in SetPasswdSettings.
Recommendations For D-Link DIR823G version 1.0.2B05, avoid using the NewPassword parameter in the SetPasswdSettings until a patch is available. As a temporary workaround, consider restricting access to the SetPasswdSettings to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-29665

Affected Products

D-Link Dir-823G